Live data from Hacker News

Your mobile data sold, without your knowledge

translate.googleusercontent.com

111–120 of 162 posts

Re: Your mobile data sold, without your knowledge

#111

Earlier quoted context omitted.

> The article assumes that the location data must have been collected because he gave an app permission to access his location. I bet they couldn’t figure out which app it was because it wasn’t an app. I worked on this story (and the others, we're still publishing [1] [2]). The dataset we bought from Tamoco didn't contain an app name for most of the data. So instead of guessing, we're open about the fact that we don'…

> I worked on this story Having access to original NRK data, is it possible to deanonymize more people (try to check your home address, NRK HQ, etc), and ask them for a list of installed apps to check if all have one in common? Although it's questionable from privacy point of view, so probably better to pursue it in legal ways.

> is it possible to deanonymize more people

There are more stories coming in the next days and weeks which will touch more on this topic.

Re: Your mobile data sold, without your knowledge

#112

Earlier quoted context omitted.

> The article assumes that the location data must have been collected because he gave an app permission to access his location. I bet they couldn’t figure out which app it was because it wasn’t an app. I worked on this story (and the others, we're still publishing [1] [2]). The dataset we bought from Tamoco didn't contain an app name for most of the data. So instead of guessing, we're open about the fact that we don'…

It could be an app - we've had startups approach us to sell location data collected from apps so I wouldn't rule anything out at this point.

Feel free to contact me if this is something you want to talk about!

Re: Your mobile data sold, without your knowledge

#113
post #38

Earlier quoted context omitted.

Anonymization in the data reselling industry is often some form of md5(lower($email)). It's a joke. They even do that for extremely small search spaces like phone numbers. It's still provided at the individual user-level and even if the anonymization is done in a way that's irreversible, you only need to know a single event for a given person and you now have their entire history. For example, there's a popular email…

> coworker saying "Oh, I bought this awesome coffee maker on Amazon last night!" This x1000. I have seen people invite others to eat lunch at restaurants that only accepted credit cards in order to elicit such a data sample.

Wait, what? Please tell us more

Re: Your mobile data sold, without your knowledge

#114
post #19

A question for the Android experts: is it possible to block or spoof location data, through a custom build? Could I have an Android phone running a program that spoofs a long steady drive from Tampa to Butte?

Why bother spoofing when you can simply turn location permission off ?

Spoofing adds noise to the data, making it worth less.

If enough people do it in a way that cannot be easily detected, the market for this sort of data will shrink quickly.

Re: Your mobile data sold, without your knowledge

#115
post #91

Earlier quoted context omitted.

You used to be able to be an anonymous SIM in the UK. (No clue whether that's still the case.) The SIM would still be tracked. Don't think whatever EU laws allowed the UK to keep some SIMS anonymous have changed since they left?

The country that still allows it is Czechia. So it's probably not an EU law that requires it.

[deleted]

Re: Your mobile data sold, without your knowledge

#116
post #98

Earlier quoted context omitted.

Thanks! That figures. They are also pretty liberal on their citizens owning guns.

Indeed we are, and the gun ownership is not minor as well (every twelfth adult normally carries a weapon).

Interesting twist on that - the EU has gun regulations, but Czechia made a law that every licensed gun owner in Czechia constitutes a part of the national defense. Sweden has a similar thing, where people in the reserve can have a fully automatic submachine gun. But it's limited to people with an explicit reserve status and the proper training, gun safe etc and further limitations, plus in practice it's not common anymore.

Re: Your mobile data sold, without your knowledge

#117

The article assumes that the location data must have been collected because he gave an app permission to access his location. I bet they couldn’t figure out which app it was because it wasn’t an app. Cell service providers can and do track your cellphone location. All they have to do is measure the signal strength of your cellphone at different towers, and they can triangulate its position. https://www.vice.com/en_us…

> The article assumes that the location data must have been collected because he gave an app permission to access his location. I bet they couldn’t figure out which app it was because it wasn’t an app. I worked on this story (and the others, we're still publishing [1] [2]). The dataset we bought from Tamoco didn't contain an app name for most of the data. So instead of guessing, we're open about the fact that we don'…

I’m cautious about what apps and services get access to my location and I feel like I have good control, but I don’t really have any idea of how carriers like Telenor and Telia handle my location data. Are you planning to touch on this or investigate it in the upcoming articles?

Re: Your mobile data sold, without your knowledge

#118

Earlier quoted context omitted.

Wait... WHAT?!?! I mean if I think about it, yeah that makes sense to have been built but WTF?!? Care to share which email client it is? It should be killed with fire!!!

Assuming you're asking a genuine question, it's Gmail. https://mail.google.com/

Do you have a source for claims that (a) google parses emails for purchase histories and (b) sells it?

https://myaccount.google.com/purchases is empty for me, and I sure do have a lot of email receipts on my gmail. It also says "Purchases made using Search, Maps, and the Assistant are organized to help you get things done, like tracking a package or reordering food".

https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase... "Google says it doesn’t use this information to sell you ads."

Google used emails for ad targeting which was mentioned in Microsoft "Scroogled" ad campaign in the US. But Google says it stopped doing so years ago.

Do I miss something?

Re: Your mobile data sold, without your knowledge

#119
post #19

A question for the Android experts: is it possible to block or spoof location data, through a custom build? Could I have an Android phone running a program that spoofs a long steady drive from Tampa to Butte?

Yes, but that does not stop the cell providers from selling your location [1]. You could also run an Android VM in the cloud and RDP to it when you want to use sketchy (edit: free) apps. This approach could have saved Bezos some trouble [2]. [1] https://www.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hu... [2] https://www.nytimes.com/2020/01/22/technology/jeff-bezos-hac...

> You could also run an Android VM in the cloud and RDP to it when you want to use sketchy (edit: free) apps. This approach could have saved Bezos some trouble

The article also points to WhatsApp as the infection vector.

I agree that anything Facebook produces is fair game as far as being sketchy goes, but it’s not the only messaging platform to have been exploited.

Do we run all messaging services in independent sandboxes in VMs?

Re: Your mobile data sold, without your knowledge

#120
post #38

Earlier quoted context omitted.

Anonymization in the data reselling industry is often some form of md5(lower($email)). It's a joke. They even do that for extremely small search spaces like phone numbers. It's still provided at the individual user-level and even if the anonymization is done in a way that's irreversible, you only need to know a single event for a given person and you now have their entire history. For example, there's a popular email…

Wait... WHAT?!?! I mean if I think about it, yeah that makes sense to have been built but WTF?!? Care to share which email client it is? It should be killed with fire!!!

I believe that GP is talking about the unroll.me service which was caught selling purchase receipts to companies like Uber a few months ago.
Post reply on HN